Skip to content
All modules
CoreModule 6 of 2790 minutes

XOR and the cost of reusing a key

Break single-byte and repeating-key XOR, then recover both plaintexts from a reused one-time pad by crib dragging.

Assumes1. Recognising encodings

By the end you can

  • Brute-force single-byte XOR and score candidates automatically
  • Detect a repeating keysize using normalised Hamming distance
  • Recover two plaintexts from a reused pad without ever learning the key
  • Explain why key reuse destroys a cipher that is otherwise information-theoretically secure
  • Recognise a stream cipher, a keystream generator and a hand-rolled 'custom' scheme as the same construction, and attack the keystream rather than the algorithm

1. Read

2. Use the tools

In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.

3. Try one now

Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.

4. Practise on the real thing

Real picoCTF challenges that use these techniques, easiest first. 27 match in total - see the full index.

Common mistakes

The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.

  • Scoring candidates by 'looks like English' rather than by a character-frequency score, which makes the search unrepeatable and slow.
  • Assuming the keysize with the lowest Hamming distance is right. Multiples of the true keysize score almost as well, and the smallest plausible one is usually the answer.
  • Trying to recover the key from a two-time pad. You never need it: the XOR of the two ciphertexts is the XOR of the two plaintexts, and cribs go straight into that.
  • Filtering single-byte candidates to printable output only. The right key often yields a plaintext carrying newlines, a length prefix or raw bytes, and a printable-only filter discards it before the score is ever read.
  • Assuming the repeating key is a word. These challenges use raw bytes as often as text, and a search restricted to ASCII keys quietly excludes the answer while still returning a confident-looking ranking.

Checkpoint

Given two ciphertexts under one reused key, recover both plaintexts and describe each crib you used.

Teaching note

The space-XOR-letter trick is the moment this module lands. Show it before the general method: once students see that the XOR of two plaintexts leaks word boundaries for free, crib dragging stops feeling like magic.

Go deeper

The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.

Every book the curriculum cites has a page in the library.